Hackers used the popular Minecraft modding platforms Bukkit and CurseForge to distribute a new 'Fractureiser' information-stealing malware through uploaded modifications and by injecting malicious code into existing projects. . According to multiple reports , the attack began when several CurseForge and Bukkit accounts were compromised and used to inject malicious code into plugins and mods, which were then adopted by popular modpacks such as 'Better Minecraft,' which has over 4.6 million downloads. Notably, many of the impacted modpacks were compromised even though they were allegedly protected by two-factor authentication. At the same time, the updates were archived immediately to not appear in public but were nonetheless pushed to users via the API. . Recent cyber threats have surfaced, targeting CurseForge and Bukkit user accounts using malware that extracts sensitive information, affecting Windows and Linux systems. Fractureiser Malware, CurseForge Security, Bukkit Mods. . LinuxSecurity.com Team
Twitter has been hit with a minor data breach incident that the social networking site believes linked to a suspected state-sponsored attack.. In a blog post published on Monday, Twitter revealed that while investigating a vulnerability affecting one of its support forms, the company discovered evidence of the bug being misused to access and steal users’ exposed information. The link for this article located at The Hacker News is no longer available. . Recent updates indicate that Twitter has uncovered a potential state-sponsored cyber intrusion tied to a small-scale data compromise involving user details.. Twitter State-Sponsored Attack, Data Breach Incident, User Information Theft. . LinuxSecurity.com Team
By penetrating the networks of downline vendors, Russian hackers gained access to a reportedly secure, isolated network, allowing them to eventually reach the control rooms of US utilities, according to the Wall Street Journal.. The state-sponsored hacking group, which poses a serious threat to critical infrastructure, has been on the watch list of the Department of Homeland Security (DHS) since 2014. Using stolen credentials gained through spear-phishing emails and watering-hole attacks, the hackers's activity long went undetected, which allowed them to steal confidential information and “familiarize themselves with how the facilities were supposed to work,” WSJ reported. The link for this article located at InfoSecurity is no longer available. . Cybercriminals from Russia breach American power grid via third-party suppliers, endangering essential infrastructure functionality.. Russian Hacking, Critical Infrastructure, Spear-Phishing, Cybersecurity Threats. . LinuxSecurity.com Team
The hackers who breached the US Office of Personnel Management accessed a second set of even more highly sensitive data, it was widely reported Friday, in revelations that make the breach one of the biggest thefts of data on federal workers. . Investigators probing the compromise have "a high degree of confidence that OPM systems containing information related to the background investigations of current, former, and prospective federal government employees, and those for whom a federal background investigation was conducted, may have been exfiltrated," Samuel Schumach, a spokesman for the personnel agency, said in a statement to Bloomberg News Friday.. Investigators probing the compromise have 'a high degree of confidence that OPM systems containing i. hackers, breached, office, personnel, management, accessed, second. . LinuxSecurity.com Team
An effective new phishing technique identified by researchers with Trend Micro allows attackers to go after information without having to spend as much time developing copies of websites. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate website, according to a Wednesday post by Noriaki Hayashi, senior threat researcher with Trend Micro. From the user's perspective, they are just browsing the regular site, and the attackers do not have to modify anything until they are ready to steal information. The link for this article located at SC Magazine is no longer available. . The attack involves a phishing page containing a proxy program that acts as a relay to a legitimate . effective, phishing, technique, identified, researchers, trend, micro, allows, attackers. . LinuxSecurity.com Team
EBay Inc. said that hackers raided its network three months ago, accessing some 145 million user records in what is poised to go down as one of the biggest data breaches in history, based on the number of accounts compromised. . It advised customers to change their passwords immediately, saying they were among the pieces of data stolen by cyber-criminals who carried out the attack between late February and early March. The link for this article located at NY Post is no longer available. . A significant security incident at Yahoo compromised 3 billion user accounts; urgent updates to account credentials are essential for protection.. eBay Data Breach, User Accounts Security, Cyber Crime Alerts. . LinuxSecurity.com Team
Hackers have compromised a private e-mail list used by Linux and BSD distributors to share information on embargoed security vulnerabilities and used a backdoor to sniff e-mail traffic, according to the moderator of the list.. In a note to The link for this article located at ZDNet is no longer available. . In a note to The link for this article located at ZDNet is no longer available.. hackers, compromised, private, e-mail, linux, distributors, share, informati. . LinuxSecurity.com Team
Just as Internet surfers have gotten wise to the fine art of phishing, along comes a new scam utilizing a new technology. Creative thieves are now switching their efforts to "vishing," which uses Voice over Internet Protocol (VoIP) phones instead of a misdirected Web link to steal user information. . The link for this article located at E-Security Planet is no longer available. . Explore the growing threat of smishing, a text message phishing tactic that endangers personal information and online security.. Vishing Scam, VoIP Security Risks, Phishing Techniques, User Safety, Online Information Theft. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.